Fedoraproject

Fedora

5353 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.33%
  • Veröffentlicht 24.06.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:34

Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely. The ...

  • EPSS 0.02%
  • Veröffentlicht 22.06.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:42:55

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 21.06.2021 20:15:09
  • Zuletzt bearbeitet 21.11.2024 06:00:37

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 18.06.2021 15:15:08
  • Zuletzt bearbeitet 10.07.2025 15:44:54

Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

Exploit
  • EPSS 0.12%
  • Veröffentlicht 17.06.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:11:16

Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.

  • EPSS 0.4%
  • Veröffentlicht 17.06.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 06:21:57

PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the defa...

  • EPSS 2.11%
  • Veröffentlicht 16.06.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:10:39

PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.

Medienbericht Exploit
  • EPSS 1.06%
  • Veröffentlicht 16.06.2021 12:15:12
  • Zuletzt bearbeitet 21.11.2024 06:09:37

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

  • EPSS 0.33%
  • Veröffentlicht 15.06.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:04:09

Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

Warnung Exploit
  • EPSS 77.97%
  • Veröffentlicht 15.06.2021 22:15:09
  • Zuletzt bearbeitet 24.10.2025 21:07:10

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.